First published: Mon Nov 09 2015(Updated: )
SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=4.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2213 has a medium severity level due to its SQL injection nature.
To fix CVE-2015-2213, update your WordPress installation to version 4.2.4 or later.
CVE-2015-2213 affects WordPress versions prior to 4.2.4.
Remote attackers can exploit CVE-2015-2213 to execute arbitrary SQL commands.
CVE-2015-2213 is an SQL injection vulnerability that allows for the execution of malicious SQL commands via manipulated comments.